CompTIA SecurityX (CAS-005)Security ArchitectureEasy
A security architect is deploying a new web application into a multi-cloud environment. The application consists of several virtual machines (VMs) and containers, each requiring specific network access controls. The architect needs to define granular, stateful inbound and outbound rules for each individual VM and container instance to restrict traffic based on IP address, port, and protocol. Which cloud native security control is best suited for this purpose?
- AWeb Application Firewall (WAF)
- BSecurity Groups
- CNetwork Access Control List (NACL)
- DVirtual Private Cloud (VPC)
Show answer & explanationAnswer & explanation
Correct answer: B. Security Groups
Security Groups are virtual firewalls that control inbound and outbound traffic to instances (VMs, containers) at the instance level. They are stateful and allow granular rules based on IP address, port, and protocol, making them ideal for the described scenario in a cloud environment.
Why the other options are wrong
- A. A WAF protects web applications from common web-based attacks (e.g., SQL injection, XSS) at the application layer, not at the network instance level for all protocols.
- C. NACLs are stateless, operate at the subnet level, and process rules in order, making them less flexible and granular than Security Groups for instance-level control.
- D. A VPC is a logically isolated network section in the cloud; it defines the network boundary but doesn't provide instance-level traffic filtering rules.
Security Groups (Cloud)
In cloud computing, Security Groups act as virtual firewalls that control inbound and outbound traffic for one or more instances (e.g., virtual machines, containers). They are stateful, allowing granular rules based on IP address, port, and protocol.
- Operate at the instance level (VMs, containers).
- Are stateful (return traffic is automatically allowed).
- Allow defining granular rules for IP, port, and protocol.
- Can be associated with multiple instances for consistent policy.
Memory trick: Security Groups Guard Granularly for Cloud Instances.